Discovering unknown advanced persistent threat using shared features mined by neural networks

被引:0
|
作者
Shang, Longkang [1 ]
Guo, Dong [2 ]
Ji, Yuede [3 ]
Li, Qiang [1 ]
机构
[1] College of Computer Science and Technology, Jilin University, Changchun,130012, China
[2] Key Laboratory of Symbolic Computation and Knowledge Engineering of Ministry of Education, Jilin University, Changchun, China
[3] Department of Electrical and Computer Engineering, George Washington University, Washington, D.C., United States
基金
中国国家自然科学基金;
关键词
Statistical tests - C (programming language) - Deep learning - Network security - Learning systems;
D O I
暂无
中图分类号
学科分类号
摘要
Command and control channel(C&C) is used in some cyber attacks to remotely control infected hosts to steal data or conduct espionage. An effective type of C&C detection methods is network flow based. The insight is that network flow is evitable because the hidden malware in the target system has to communicate with the external C&C server to either receive commands or send data. However, existing network flow-based methods face two challenges to efficiently detect C&C of APT(Advanced persistent threat) attacks, i.e., stealth and flexible attack techniques. To combat these two challenges, we design a new network flow-based C&C detection method. Our work is inspired from two observations that different APT attacks share the same intrusion tools and services, and the unknown malware evolves from existing one. Therefore, the malwares of different groups have some shared attributes that are not easy to find, which leads to some hidden shared features in the network flows between the malware and the C&C server in different attacks. Based on this, we propose a method to detect the hidden C&C channel of unknown APT attacks. First, we use deep learning techniques to mine the shared network flow features from the known multi-class attack flows. Later, we use an appropriate classifier to detect the C&C network flow. Finally, we test our method on public available dataset. The experimental results show that our method can achieve up to F1 score of 0.968 when dealing with unknown malicious network flows. This will help discover unknown APT attacks. © 2021 Elsevier B.V.
引用
收藏
相关论文
共 50 条
  • [21] An advanced persistent threat in 3G networks: Attacking the home network from roaming networks
    Xenakis, Christos
    Ntantogian, Christoforos
    COMPUTERS & SECURITY, 2014, 40 : 84 - 94
  • [22] Stabilization of unknown nonlinear systems using neural networks
    Fourati, Fathi
    Chtourou, Mohamed
    Kamoun, Mohamed
    APPLIED SOFT COMPUTING, 2008, 8 (02) : 1121 - 1130
  • [23] Coverage control in unknown environments using neural networks
    Alireza Dirafzoon
    Saba Emrani
    S. M. Amin Salehizadeh
    Mohammad Bagher Menhaj
    Artificial Intelligence Review, 2012, 38 : 237 - 255
  • [24] Coverage control in unknown environments using neural networks
    Dirafzoon, Alireza
    Emrani, Saba
    Salehizadeh, S. M. Amin
    Menhaj, Mohammad Bagher
    ARTIFICIAL INTELLIGENCE REVIEW, 2012, 38 (03) : 237 - 255
  • [25] Learning with an augmented (unknown) class using neural networks
    Engelbrecht, E. R.
    du Preez, J. A.
    SCIENTIFIC AFRICAN, 2020, 10
  • [26] Advanced persistent threat detection via mining long-term features in provenance graphs
    Xu, Fan
    Zhao, Qinxin
    Liu, Xiaoxiao
    Wang, Nan
    Gao, Meiqi
    Wen, Xuezhi
    Zhang, Dalin
    FRONTIERS OF COMPUTER SCIENCE, 2025, 19 (10)
  • [27] Detection of advanced persistent threat using machine-learning correlation analysis
    Ghafir, Ibrahim
    Hammoudeh, Mohammad
    Prenosil, Vaclav
    Han, Liangxiu
    Hegarty, Robert
    Rabie, Khaled
    Aparicio-Navarro, Francisco J.
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2018, 89 : 349 - 359
  • [28] APTGuard : Advanced Persistent Threat (APT) Detections and Predictions using Android Smartphone
    Chuan, Bernard Lee Jin
    Singh, Manmeet Mahinderjit
    Shariff, Azizul Rahman Mohd
    COMPUTATIONAL SCIENCE AND TECHNOLOGY, 2019, 481 : 545 - 555
  • [29] Anticipating Advanced Persistent Threat (APT) Countermeasures using Collaborative Security Mechanisms
    Mirza, Natasha Arjumand Shoaib
    Abbas, Haider
    Khan, Farrukh Aslam
    Al Muhtadi, Jalal
    2014 INTERNATIONAL SYMPOSIUM ON BIOMETRICS AND SECURITY TECHNOLOGIES (ISBAST), 2014, : 129 - 132
  • [30] Evolving Advanced Persistent Threat Detection using Provenance Graph and Metric Learning
    Ayoade, Gbadebo
    Akbar, Khandakar Ashrafi
    Sahoo, Pracheta
    Gao, Yang
    Agarwal, Anmol
    Jee, Kangkook
    Khan, Latifur
    Singhal, Anoop
    2020 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2020,